Registered Protected-Action Authorization

Registered Protected-Action Authorization A sequence diagram generated by Archify. start Agent turn authenticated session + Agent launch Run + scoped TTL identity agentctl action + Runtime credential resolve trusted Human / Agent / Run verify chain, idempotency, trusted facts evaluate bouncer-v5 + risk-v1 ALLOW / DENY / REQUIRE_APPROVAL append redacted hash-chained evidence owner; + distinct reviewer if critical persist exact binding + one use retry same request + approval id atomically consume capability 1 → 0 final transaction: deny revocation race execute only if recheck passes durable safe result safe receipt; exact replay is inert Run terminal: revoke credential + claims Issue trusted Run identity Decide from backend facts Approve exact temporary authority Consume, recheck, execute, close Human authority · Sequence participant Human authority React UI · Sequence participant React UI Fastify control · Sequence participant Fastify control Codex Runtime · Sequence participant Codex Runtime RuntimeGateway · Sequence participant RuntimeGateway Policy + approval · Sequence participant Policy + approval JsonStore + audit · Sequence participant JsonStore + audit Protected action · Sequence participant Protected action Legend request return security async trace